TL;DR
- RBI (NBFC – Responsible Business Conduct) Directions, 2025 already require NBFCs to publish an up-to-date recovery agency list on their website. That obligation is not new in 2026.
- The 2026 amendment, part of the same instrument family covered earlier in this series, adds a specific timing rule effective January 1, 2027: modifications must be reflected within 7 calendar days.
- Terminations carry a stricter, separate standard: immediate reflection, not within 7 days.
- A parallel bank-side circular reportedly carries a similar obligation, but this is not confirmed identical in scope or figure. Bank compliance teams should check the primary circular rather than assume parity.
- In practice, the failure point is rarely a lack of tooling. It’s a handoff gap between legal/procurement, who know when a contract ends, and the web-publishing team, who maintains the disclosure.
- Compliance software supporting this requirement needs to treat the agency list as a governed, versioned, timestamped artifact, not a static webpage edit.
Your Recovery Agency Disclosure Obligation Started in 2025, Not 2027
If your compliance calendar has flagged January 2027 as the date this obligation begins, that’s incomplete. The obligation to publish a recovery agency list already exists. The RBI (NBFC – Responsible Business Conduct) Directions, 2025, at what secondary sources cite as para 97, already require NBFCs to host an up-to-date list of the recovery agencies they engage on their website.
We flag this as secondary-sourced: we have not independently checked this citation against RBI’s primary text, and readers should verify the paragraph number before citing it in a filing. What is not in dispute is the substance: the baseline requirement exists, and it does not specify a timeline for how quickly an update needs to happen. That gap is exactly what the 2026 amendment closes.
Many NBFCs already publish some version of this list. Few have a documented process for how quickly it gets updated when the underlying vendor relationship changes. That absence of a process is the actual subject of this post.
The 2026 Amendment Adds Two Different Clocks, Not One
The RBI (NBFC – Responsible Business Conduct) Third Amendment Directions, 2026, effective January 1, 2027, is the instrument that introduces a timing standard. It does so with two separate clocks, not one uniform deadline:
- Modifications to the recovery agency list, such as adding a new agency or updating an existing agency’s details, must be reflected within 7 calendar days.
- Terminations must be reflected immediately, a materially stricter and separate standard from the 7-day window.

Termination Is the Sharper Risk, Even Though It Has the Stricter Deadline
It’s worth pausing on why terminations get the tighter deadline instead of the looser one you might expect for a more disruptive change.
A modification, adding an agency or updating its contact details, is a data accuracy problem. A stale entry there is an inconvenience and a compliance gap, but it doesn’t put a borrower at immediate risk.
A termination is different. If an agency’s contract ends and the website still lists it as authorized, that agency, or someone claiming to act on its behalf, can approach a borrower who has checked the website in good faith and reasonably concluded the contact is legitimate. That gap creates a live channel for a borrower to be misled by someone with no current authority to collect on the NBFC’s behalf. The immediate standard exists because the cost of delay in this specific case falls on the borrower, not just on the lender’s compliance file.
The Bank-Side Picture Is Reported, Not Confirmed
A parallel circular, RBI/2026-2027/223, dated August 6, 2026, is reported to carry a similar obligation for banks. We have not confirmed that this circular sets the same 7-day and immediate figures as the NBFC amendment, and it may differ in scope, in the entities it applies to, or in how it defines a modification versus a termination.
Bank compliance teams should treat this as a signal to check the primary circular directly, not as confirmation that the NBFC timeline applies to them unchanged. Assuming parity here without verification is itself a compliance risk.
What Actually Causes a Stale Disclosure List: A Handoff Gap, Not a Technology Gap
Here is the part of this that most compliance calendars skip: the list doesn’t go stale because publishing a webpage is hard. It goes stale because the two functions that need to coordinate don’t share a trigger.
Legal or procurement knows the day a recovery agency’s contract ends. That knowledge sits inside a contract management process, an approval chain, a termination notice. The web-publishing team, whether that’s marketing, IT, or an external vendor, has no visibility into that event unless someone tells them, and tells them on a deadline. Without a governed workflow that forces same-day notice from legal/procurement to web publishing, the gap opens by default, not by exception. Nobody decides to leave a terminated agency on the list. It happens because no one owned the handoff.
This is a specific, checkable claim about where the failure originates: the absence of a mandatory, timestamped notice step between the function that knows about the change and the function that publishes it.

What This Requires of Recovery and Compliance Software
Software supporting recovery agency disclosure compliance for banks and NBFCs needs to treat the agency list as a governed, versioned artifact, not a page that gets edited manually when someone remembers to.
Concretely, this means:
- A timestamped change record for every addition, edit, and termination on the list.
- An approval step before any change is published, so the record shows who authorized the change and when.
- A provable “who changed what and when” audit trail that can be produced on demand, not reconstructed after the fact.
- Workflow logic that distinguishes a modification, which carries a 7-day SLA, from a termination, which carries an immediate SLA, and routes each with different urgency handling.
iTuring’s Model Governance module was built around a different object: model decisions, with an immutable audit trail, maker-checker approval, and versioned change history designed for regulators asking how and why a specific credit or collections decision was made. The same underlying governance discipline, provable timestamps, forced approval, a record that can’t be quietly edited after the fact, generalizes to any object that needs a defensible change history with a hard deadline attached, including a vendor disclosure list. This is a statement about the discipline transferring, not a claim that Model Governance manages website publishing today.
A Likely Related Requirement: What the Disclosure Probably Needs to Show
One more detail worth flagging, though it comes with a clear caveat. A structurally similar clause in the same amendment family, covering DSA and DMA disclosures, is cited by one draft source at para 101C as requiring agency-level detail along with the period of engagement, meaning start and end dates for the relationship.
It’s reasonable to infer that the recovery agency list will need to show similar detail, since the underlying purpose, letting a borrower verify current authorization, depends on knowing not just that an agency exists but for how long it has been engaged. This is an inference drawn from an analogous clause, not a confirmed requirement for the recovery agency list specifically. Treat it as a planning input, not a settled compliance checklist item.
Where This Fits in the Compliance Sequence
Disclosure is what you publish once an agency is already engaged. It says nothing about how that agency was vetted before it ever reached the list. A later post in this series covers recovery agency due diligence, the checks that should happen before an agency’s name goes on the site at all, so the disclosure obligation covered here isn’t the only safeguard standing between your NBFC and a borrower who’s misled by an outdated list.


